A significant supply chain attack recently targeted the Virtualizor server management panel, where hackers exploited Border Gateway Protocol (BGP) routing to redirect legitimate updates to their own servers, allowing them to install backdoors and gain administrative access. The attack involved Softaculous, the developer of Virtualizor, and Hetzner, a German cloud provider.
By hijacking the 162.55.80.0/24 subnet associated with Hetzner, attackers published a more specific route, making their fraudulent announcement appear legitimate.
The attack was exacerbated by the lack of a proper signature verification mechanism for Virtualizor updates, which relied solely on TLS certificates for security. This allowed attackers to intercept domain validation traffic from Let’s Encrypt and obtain valid TLS certificates, thereby bypassing essential security protocols. Softaculous is currently relying on administrator reports to assess the damage, as many compromised servers may not yet be identified. Administrators are advised to check for unauthorized SSH keys and update their credentials.